CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84269
6.5 MEDIUM

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to …

Sep 1, 2026
CVE-2026-84268
8.8 HIGH

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() …

Sep 1, 2026
CVE-2026-84267
4.3 MEDIUM

A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer …

Sep 1, 2026
CVE-2026-84232
5.4 MEDIUM

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for …

Sep 1, 2026
CVE-2026-84207
5.4 MEDIUM

Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers …

Sep 1, 2026
CVE-2026-84206
4.3 MEDIUM

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. …

Sep 1, 2026
CVE-2026-84205
6.5 MEDIUM

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the …

Sep 1, 2026
CVE-2026-84204
6.5 MEDIUM

GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from …

Sep 1, 2026
CVE-2026-84203
8.1 HIGH

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with …

Sep 1, 2026
CVE-2026-84202
8.8 HIGH

ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories …

Sep 1, 2026
CVE-2026-84201
7.1 HIGH

appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT …

Sep 1, 2026
CVE-2026-84153
6.3 MEDIUM

A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation …

Sep 1, 2026
CVE-2026-79687
9.0 CRITICAL

Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem …

Sep 1, 2026
CVE-2026-79682
8.8 HIGH

Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Sep 1, 2026
CVE-2026-61779
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61778
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61777
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61776
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61775
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61774
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61773
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61772
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61771
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61770
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61769
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61768
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61767
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61766
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61765
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61764
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61763
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61762
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61761
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61760
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61759
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61758
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61757
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61756
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61755
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61754
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61753
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61752
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61751
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-61750
7.8 HIGH

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Sep 1, 2026
CVE-2026-58567
8.8 HIGH

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root …

Sep 1, 2026
CVE-2026-51770

Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a …

Sep 1, 2026
CVE-2026-51769

Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted …

Sep 1, 2026
CVE-2026-51768

Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending …

Sep 1, 2026
CVE-2026-51767

Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a …

Sep 1, 2026
CVE-2026-49329
7.5 HIGH

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass …

Sep 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.